ApplyPAdESLongTermValidation
Assinaturas digitais
Descrição
Promove um PDF já assinado a PAdES-B-LT em uma única chamada, gravando o resultado em um arquivo
Sintaxe
Delphi
Function TPDFlib.ApplyPAdESLongTermValidation(Const InputFile, Password, OutputFile, FieldName: WideString; Options: Integer): Integer;Parâmetros
| InputFile | The signed PDF. |
|---|---|
| Password | A senha para abri-lo, ou uma string vazia. |
| OutputFile | The augmented PDF to write. |
| FieldName | A signature field to process, or an empty string to process every signature into one revision. |
| Options | A PADES_LTV_* bit mask; 0 selects PADES_LTV_DEFAULT. |
Opções
PADES_LTV_WRITE_VRI (1) | Gravar uma entrada VRI para cada assinatura. |
|---|---|
PADES_LTV_FETCH_OCSP (2) | Consultar o respondedor OCSP de cada link. |
PADES_LTV_FETCH_CRL (4) | Recorrer à CRL quando o OCSP não retornar nada. |
PADES_LTV_FOLLOW_AIA (8) | Seguir os endereços do emissor para completar o caminho. |
PADES_LTV_SKIP_EXISTING (16) | Do not re-add material whose bytes are already staged. |
PADES_LTV_SKIP_ROOT_REVOCATION (32) | Do not ask for a self-issued root's status. |
PADES_LTV_DEFAULT (63) | Tudo o que está acima; selecionado quando Options é 0. |
Valores retornados
| 1 | The promotion succeeded. |
|---|---|
| 2 | O arquivo de entrada não pôde ser lido. |
| 3 | O PDF de entrada não pôde ser interpretado. |
| 10 | A saída não pôde ser gravada. |
| 11 | O document security store não pôde ser adicionado. |
| 20 | No such signature field. |
| 21 | No processed signature carried a readable certificate. |
GetPAdESLTVError informa o motivo para qualquer valor diferente de 1.
Observações
The signer certificate path is built from the signature's own CMS, and the remaining issuers are followed through the caIssuers addresses the certificates name when PADES_LTV_FOLLOW_AIA is set. Revocation is gathered for each link - OCSP first, then a CRL - and, with the certificates, written into the document security store by a single incremental update.
Material idêntico ao que já foi preparado é gravado uma única vez e referenciado por todas as assinaturas que precisarem dele, de modo que uma certificate authority compartilhada ao longo do caminho ou entre assinaturas não aparece duplicada. Uma entrada VRI só é gravada quando tem um certificado para apontar, então nunca surge uma entrada vazia
Um respondedor inalcançável não faz a chamada falhar: a promoção segue com o que foi coletado, e GetPAdESLTVCertificateCount, GetPAdESLTVCRLCount, GetPAdESLTVOCSPCount e GetPAdESLTVError reportam o que foi obtido e o motivo de algo ter ficado de fora.
Exemplo
PDF.SetTimeStampOptions(2, 1, 1, 15000, '');
if PDF.ApplyPAdESLongTermValidation('signed.pdf', '', 'signed-lt.pdf', '', 0)<> 1 then
ShowMessage(PDF.GetPAdESLTVError);Veja também
ApplyPAdESLongTermValidationToStream, GetSignatureCertificateChainLength, AddPAdESDSSOCSPFromCertificates